Register a free account

ne nw
Crawlability Inc. Files for SEO Technology Patent
se sw

Go Back   Forum Index > Internet > Security Alerts and vulnerabilities
The Software Store

Security Alerts and vulnerabilities Lets keep abreast on the latest threats by posting those findings here..

Reply
 
Thread Tools Display Modes
  #1  
Old 11-13-2006, 05:20 PM
Symantec's Avatar
Symantec Symantec is offline
Senior Member
 
Join Date: Oct 2006
Posts: 300
Exploits get Visual

Exploits get Visual
<p>On October 31st, Microsoft released a Security Advisory entitled <a href="http://www.microsoft.com/technet/security/advisory/927709.mspx">Vulnerability in Visual Studio 2005 Could Allow Remote Code Execution</a>. At this time, a vendor supplied patch has not been released against the vulnerability. It allows a remote file to be downloaded and executed whenever a vulnerable user visits a malicious Web site. We have confirmed that it is being actively exploited in the wild.</p>

<p>To proactively detect the exploitation of this vulnerability, Symantec Security Response released <a href="http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-110115-5513-99"> Bloodhound.Exploit.95</a> on November 1. Since then, we have received steady number of Bloodhound.Exploit.95 submissions. The submitted files are generally .html files from malicious Web sites, which use the vulnerability to download further malware, most of which have turned out to be <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-042013-1813-99">Trojan.Galapoper.A</a> variants. Trojan.Galapoper.A is a Trojan that downloads and executes remote files, which are generally other malware. Other downloaded files have turned out to be general Infostealers. </p>

<p>Once again this demonstrates the need to practice safe computing until a vendor supplied patch is made available. And think twice before visiting a suspicious Web site – you may get more than you bargained for.<br />
</p>
http://www.symantec.com/enterprise/security_response/weblog/2006/11/visual_confirmation_vulnerabil.html
http://www.symantec.com/enterprise/security_response/weblog/2006/11/visual_confirmation_vulnerabil.html
Fri, 03 Nov 2006 23:40:06 -0800
Reply With Quote
Sponsored Links

Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 12:28 AM.


234x60
Bulletin Board Custom Version by Mobo
Copyright © 2004-2007 Cyberanswers.org All rights reserved